Description
Multiple Cisco products are affected by a vulnerability in the Snort 3 Visual Basic for Applications (VBA) feature which could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. 
 
This vulnerability is due to lack of proper error checking when decompressing VBA data. An attacker could exploit this vulnerability by sending a crafted VBA data to the Snort 3 Detection Engine on the targeted device. A successful exploit could allow the attacker to cause the Snort 3 Detection Engine to unexpectedly restart causing a a denial of service (DoS) condition.
Published: 2026-03-04
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the Snort 3 Visual Basic for Applications (VBA) decompression routine, where the system fails to perform adequate error checking. This flaw can be exploited by sending a specially crafted VBA payload to the Snort 3 Detection Engine, causing it to crash and trigger a restart. The resulting denial of service disables the host’s intrusion detection capability without requiring authentication, representing a moderate risk of service denial (CVSS 5.8).

Affected Systems

Cisco Secure Firewall Threat Defense, Cisco UTD SNORT IPS Engine, and Cisco Cyber Vision are affected. The advisory does not list specific firmware or software versions; users should consult the referenced Cisco advisory for precise guidance on which releases are impacted.

Risk and Exploitability

The exploit is carried out remotely from an unauthenticated attacker who crafts VBA data and delivers it to the targeted device. The EPSS score is less than 1%, indicating a low probability of active exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Despite the moderate CVSS rating, the low exploit likelihood coupled with the critical role of Snort 3 in threat detection suggests that the risk is moderate but should not be ignored, particularly in high‑visibility or regulated environments.

Generated by OpenCVE AI on April 16, 2026 at 13:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest Cisco Secure Firewall Threat Defense update that addresses the Snort 3 VBA decompression issue.
  • If the patch cannot be applied immediately, disable the Snort 3 Detection Engine or block incoming VBA payloads to prevent the denial of service until the update is applied.
  • Continuously monitor firewall logs for repeated crashes or service restarts, and consider activating alerting on unexpected engine restart events to detect exploitation attempts.

Generated by OpenCVE AI on April 16, 2026 at 13:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 05 Mar 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco cisco Utd Snort Ips Engine Software
Cisco cyber Vision
Cisco secure Firewall Threat Defense
Vendors & Products Cisco
Cisco cisco Utd Snort Ips Engine Software
Cisco cyber Vision
Cisco secure Firewall Threat Defense

Wed, 04 Mar 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 04 Mar 2026 18:00:00 +0000

Type Values Removed Values Added
Description Multiple Cisco products are affected by a vulnerability in the Snort 3 Visual Basic for Applications (VBA) feature which could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash.&nbsp; &nbsp; This vulnerability is due to lack of proper error checking when decompressing VBA data. An attacker could exploit this vulnerability by sending a crafted VBA data to the Snort 3 Detection Engine on the targeted device. A successful exploit could allow the attacker to cause the Snort 3 Detection Engine to unexpectedly restart causing a a denial of service (DoS) condition.
Title Cisco Secure Firewall Threat Defense Software Snort 3 Visual Basic for Application Denial of Service Vulnerability
Weaknesses CWE-369
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L'}


Subscriptions

Cisco Cisco Utd Snort Ips Engine Software Cyber Vision Secure Firewall Threat Defense
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-03-04T21:32:46.370Z

Reserved: 2025-10-08T11:59:15.356Z

Link: CVE-2026-20057

cve-icon Vulnrichment

Updated: 2026-03-04T21:32:41.238Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-04T18:16:20.320

Modified: 2026-03-05T19:39:11.967

Link: CVE-2026-20057

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T13:30:16Z

Weaknesses